The governance triangle
Section titled “The governance triangle”Cloud governance rests on three equally important pillars. Weakness in any one pillar destabilises the entire framework.
The three pillars form an equilateral triangle: Security Governance stands at the apex, Financial Governance and Operational Governance form the base. Weakness in one pillar destabilises the whole framework — an organisation that operates only Security Governance loses cost control and operational stability; one that focuses only on Operational Governance opens security gaps and budget risk.
Pillar 1: Security Governance
Section titled “Pillar 1: Security Governance”Purpose: Ensure that cloud resources introduce no security vulnerabilities, that regulatory requirements are met, and that compliance is demonstrable.
Core Security Guardrails
Section titled “Core Security Guardrails”| Guardrail | Description | Enforcement |
|---|---|---|
| Geographic restriction | Resources only in approved cloud regions within Germany | Hard-Mandatory |
| Encryption at rest | All data resources encrypted (AES-256 minimum) | Hard-Mandatory |
| No public access without allowlist | No unrestricted public endpoints | Hard-Mandatory |
| IAM Least Privilege | No wildcard permissions in production | Hard-Mandatory |
| MFA for all human access | Console and API access with MFA | Hard-Mandatory |
| Immutable audit logs | Logs in a separate, non-deletable logging project | Hard-Mandatory |
Security Governance Maturity
Section titled “Security Governance Maturity”| Level | Characteristics |
|---|---|
| Level 1: Reactive | Security problems are fixed after incidents. No preventive controls. |
| Level 2: Preventive | Core guardrails implemented. New resources are compliant. Legacy estate still open. |
| Level 3: Proactive | Continuous compliance monitoring. Automatic detection and alerting on deviations. |
| Level 4: Predictive | Automated remediation. Security reviews in CI/CD. Threat modelling for new architectures. |
Realistic target: Level 3 after 12 months.
Pillar 2: Financial Governance
Section titled “Pillar 2: Financial Governance”Purpose: Ensure that cloud spend is transparent, traceable and within budget.
Core Financial Guardrails
Section titled “Core Financial Guardrails”| Guardrail | Description | Enforcement |
|---|---|---|
| Mandatory tagging (6 tags) | No resource without a complete tag set | Hard-Mandatory (deployment blocked) |
| Budget alerts | Alert at >80 % and >100 % of monthly budget | Automatically configured |
| Anomaly detection | Alert at >20 % daily deviation from 7-day average | Automatically configured |
| Sandbox budget caps | Maximum monthly budget per sandbox project | Hard-Cap (resources stopped) |
| Reserved Instance policy | Baseline workloads must be covered with RIs | Advisory (recommended, not enforced) |
Pillar 3: Operational Governance
Section titled “Pillar 3: Operational Governance”Purpose: Ensure that cloud resources are operated, monitored and maintained to defined standards.
Core Operational Guardrails
Section titled “Core Operational Guardrails”| Guardrail | Description | Enforcement |
|---|---|---|
| IaC mandatory for production | No manual portal configuration in production | Process + audit |
| Backup policy | All production data resources with backup policy | Advisory + compliance scan |
| Monitoring minimum requirements | CPU, memory, disk, error rate for all services | Mandatory for go-live |
| Runbook requirement | Every production service has an incident response runbook | Pre-go-live checklist |
| Patch management | Managed services: automatic. IaaS: within 30 days | Monitoring |
What good versus poor governance looks like in practice
Section titled “What good versus poor governance looks like in practice”| Poor Governance | Good Governance | |
|---|---|---|
| Security | Security reviews as a one-time gate before go-live | Continuous security as code in every pipeline |
| Financial | Monthly cost shock, unknown cost drivers | Daily visibility, teams own their cloud costs |
| Operational | Incident → chaos, nobody knows who is responsible | Alert → runbook → defined team responds in <30 min |
Practical steps
Section titled “Practical steps”- Governance maturity assessment: Where does your organisation stand in each pillar?
- Core guardrails implemented as Policy-as-Code
- Governance KPI dashboard configured
- Monthly governance review anchored in the CCoE rhythm